
Riproduzione in laboratorio di CVE-2026-34040: bypassa i plugin AuthZ di Docker/Moby utilizzando corpi di richiesta di dimensioni eccessive (>1 MB) per creare contenitori privilegiati con accesso all'host.
KO: Un progetto di riproduzione pratica di una vulnerabilità che bypassa il plugin di autorizzazione (AuthZ) di Docker/Moby utilizzando un corpo della richiesta superiore a 1MB. EN: A lab reproduction of a vulnerability that bypasses Docker (Moby) authorization (AuthZ) plugins using an oversized (>1MB) request body.
| Item | Value |
|---|
| CVE | CVE-2026-34040 |
| CVSS 3.1 | 8.8 (High) — CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| CWE | CWE-288 (Authentication Bypass Using an Alternate Path or Channel), CWE-863 (Incorrect Authorization) |
| Affected | moby/moby < 29.3.1, docker/docker < 29.3.1, moby/moby/v2 < 2.0.0-beta.8 |
| Fixed in | 29.3.1, 2.0.0-beta.8 |
| Root cause | Incomplete fix for CVE-2024-41110 |
| Patch commit | moby/moby@e89edb1 |
KO: Il vettore CVSS ufficiale è
AV:L(Locale). Lo scenario valutato è un utente con privilegi bassi che ha accesso locale all'API Docker (tipicamente/var/run/docker.sock). Anche questo PoC utilizza solo il socket UNIX locale. EN: The official CVSS vector isAV:L(Local). The rated scenario is a low-privileged user with local Docker API access (typically/var/run/docker.sock). This PoC uses the local UNIX socket only.
KO:
- Una richiesta di creazione di un container privilegiato di dimensioni normali viene bloccata dal plugin AuthZ (HTTP 403).
- La stessa richiesta con padding superiore a 1MB bypassa il controllo AuthZ.
- La richiesta bypassata raggiunge il demone Docker e crea un container privilegiato.
- Con la combinazione privilegiato + bind mount dell'host, è possibile dimostrare la lettura di file dell'host e l'esecuzione di comandi sull'host.
EN:
- A normal-sized privileged container-create request is blocked by the AuthZ plugin (HTTP 403).
- The same request padded beyond 1MB bypasses the AuthZ check.
- The bypassed request reaches the Docker daemon and creates a privileged container.
- With privileged + host bind mount, host file read and host command execution can be demonstrated.
KO: Questa CVE di per sé non legge
/etc/shadowné esegue RCE direttamente. La vulnerabilità consiste nel bypass di una richiesta API Docker che AuthZ dovrebbe bloccare; i passaggi successivi (lettura file, chroot, esecuzione comandi) sono demo dell'impatto che abusano di funzionalità normali di Docker/Linux. EN: The CVE itself does not read/etc/shadowor perform RCE directly. The vulnerability is the bypass of a Docker API request that AuthZ should block; the later steps (file read, chroot, command execution) are impact demos that abuse normal Docker/Linux features.
.
├── README.md
├── poc.py # Working PoC (local UNIX socket only)
├── requirements.txt # Python standard library only
├── LICENSE
├── lab/
│ ├── authz.rego # OPA policy: blocks privileged + host-root bind
│ └── daemon.json # Registers the AuthZ plugin
└── docs/
├── concepts.md # 개념 / Concepts
├── lab-setup.md # 환경 구성 / Lab setup
├── how-it-works.md # 동작 원리 / How it works (source-level)
├── usage.md # 사용법 / Usage
├── troubleshooting.md # 문제 해결 / Troubleshooting
└── references.md # 참고 / References
KO: Affinché questo PoC sia significativo, tutte le seguenti condizioni sono necessarie. EN: All of the following are required for this PoC to be meaningful.
| Condition | Required | Reason |
|---|---|---|
Local Docker API access (/var/run/docker.sock) | Yes | The PoC sends requests to the socket |
| AuthZ plugin enabled with a body-inspecting policy | Yes | The bypass target is the AuthZ check |
| Docker/Moby < 29.3.1 | Yes | Patched versions reject oversized bodies |
alpine image present locally | Recommended | Otherwise create returns 404 No such image |
# 1) Pull the image used by the PoC
sudo docker pull alpine
# 2) Run the non-destructive bypass check
sudo python3 poc.py --mode check
Expected on a vulnerable target / 취약 대상에서의 기대 결과:
small request -> HTTP 403 (AuthZ blocks)
oversized request -> HTTP 201 or HTTP 404 (AuthZ bypassed; daemon processed it)
KO: Un
404 No such imageè comunque prova del bypass — significa che la richiesta ha superato AuthZ (non 403) ed è arrivata alla fase di ricerca dell'immagine del demone. Per evitare confusione in una demo, esegui il pull dialpinein anticipo. EN: A404 No such imageis still evidence of bypass — the request passed AuthZ (not 403) and reached the daemon's image lookup. Pullalpinebeforehand to avoid confusion in a demo.
Vedi docs/usage.md per l'uso completo. / See docs/usage.md for full usage.
KO: Utilizza solo in un ambiente di laboratorio isolato di tua proprietà o per il quale hai esplicitamente ricevuto autorizzazione. Non eseguire contro API Docker remote, server di terze parti, ambienti di produzione o endpoint Docker esposti a Internet. Le modalità demo d'impatto (
rce-proof,host-command,reverse-shell-local) richiedono un flag di conferma esplicito. EN: Use only in an isolated lab you own or are explicitly authorized to test. Do not run against remote Docker APIs, third-party servers, production, or internet-exposed Docker endpoints. The impact-demo modes (rce-proof,host-command,reverse-shell-local) require an explicit confirmation flag.
See docs/references.md. / Vedi docs/references.md.